airflow-users mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From Ash Berlin-Taylor <...@apache.org>
Subject [CVE-2019-12417] Apache Airflow stored xss and local file disclosure vulnerability <= 1.10.5
Date Wed, 30 Oct 2019 09:06:24 GMT
CVE-2019-12417: Stored XSS and Local File Disclosure vulnerability 

  Versions Affected:
  <= 1.10.5

  Description:
    A malicious admin user could edit the state of objects in the Airflow metadata database
to execute arbitrary javascript on certain page views. This also presented a Local File Disclosure
vulnerability to any file readable by the webserver process.

  Credit:
    Thanks to Pawel.Kurylowicz (of securing.pl), and Frantisek Uhrecky and Marek Takac (both
of citadelo.com) for all independently reporting this vulnerability. 
 
Thanks,
Ash
Apache Airflow PMC member
Mime
View raw message